krabwebuninstall.exe

Krab Web

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application krabwebuninstall.exe by Krab Web has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. Additionally, the file is typically installed by a number of programs including Krab Web by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Krab Web  (signed and verified)

MD5:
46fe33c43befc650403de7054d8a6f5b

SHA-1:
55773bed167d50bf00b73d0bd8a55552a6492d0c

SHA-256:
18479d9dbb6342f79b38bf6591c9a9334f531c1ba8cd2ff7810203036b6828b2

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 1:03:57 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3316

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.141019

ESET NOD32
Win32/BrowseFox.C potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.KrabWeb.Q
14.10.19.16

VIPRE Antivirus
Threat.4741131
33706

File size:
254.2 KB (260,272 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\krab web\krabwebuninstall.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
6/8/2014 6:00:00 PM

Valid to:
6/17/2015 6:00:00 AM

Subject:
CN=Krab Web, O=Krab Web, L=Santa Monica, S=California, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0572744C4944FF55FB05A9A82A78D271

File PE Metadata
Compilation timestamp:
12/5/2009 3:52:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:BZ+11j0Fahhy/1RWBT5/0XoUC3//vqwZm/G/Hc8u:88Chs1s15sXnC3nvqp/G/8z

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8661

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file krabwebuninstall.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Krab Web  by Yontoo Technology, Inc.
Krab Web is an advertising supported browser extension also known as adware and is designed to deliver ads to the user's Internet browser as banners, context text-links and transitionals ads. The injected ads are not affiliated with the underlying website on which they appear.
krabweb.net/support
81% remove it
 
Powered by Should I Remove It?

Remove krabwebuninstall.exe - Powered by Reason Core Security